Description
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents.

The code then dereferences the NULL gw (gw->gw_id) and passes it to mqtt_sn_gw_destroy(), reaching k_mem_slab_free(&gateways, NULL). With CONFIG_MEM_SLAB_POINTER_VALIDATE enabled this triggers k_panic(); in the default configuration it performs a write through the NULL pointer ((char )mem = slab->free_list;) and corrupts the slab free list. The outcome is a crash/kernel panic or, on targets where address 0 is writable, silent memory-allocator corruption.

The vulnerable branch runs whenever the connected MQTT-SN gateway fails to answer keepalive PINGREQs for the configured number of retries. This condition is controlled by the remote peer: a malicious or compromised gateway, or an on-path/adjacent attacker that advertises itself as a gateway and then stops responding (or blackholes the real gateway's PINGRESPs), forces the client into the defect. MQTT-SN runs over UDP and no authentication is required.

The impact is a remotely triggerable denial of service (availability) of the affected MQTT-SN client; there is no attacker-controlled data written. The sibling remover process_advertise() uses SYS_SLIST_FOR_EACH_CONTAINER_SAFE and is not affected. The fix assigns the macro's return value to gw.
Published: 2026-09-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Zephyr MQTT‑SN client contains a NULL pointer dereference in process_ping() when it removes a gateway that has failed to respond to keepalive PINGREQs. The list traversal macro returns no value, leaving the pointer NULL; subsequent code dereferences it during k_mem_slab_free(), corrupting the memory slab free list or triggering a kernel panic when pointer validation is enabled. The result is a crash or subtle memory corruption that denies service to the client. No attacker‑controlled data is written, and there is no additional privilege escalation.

Affected Systems

The flaw impacts the Zephyr Project’s Zephyr real‑time operating system, specifically the MQTT‑SN client implementation in subsys/net/lib/mqtt_sn. No specific release is listed; the patch can be found in commit bd21e954c36be105a374bbc090623810f1a17ee3 in the Zephyr source tree, so administrators must verify their Zephyr version and apply any available update that includes this fix.

Risk and Exploitability

The vulnerability scores a CVSS of 7.5; EPSS is 0.00336 (< 1%) and it is not listed in the CISA KEV catalog. The attack is remote: an attacker or compromised gateway can stop responding to MQTT‑SN PINGREQs over UDP, forcing the client to hit the defect. Because MQTT‑SN operates over UDP without authentication, any host on the network can trigger the denial of service, making the risk moderate to high for exposed devices.

Generated by OpenCVE AI on September 15, 2026 at 16:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a version that incorporates commit bd21e954c36be105a374bbc090623810f1a17ee3 or apply the patch directly to the MQTT‑SN client source.
  • If an update is not possible, disable or restrict the MQTT‑SN client or configure a very low keepalive retry threshold to minimize the window of the defect.
  • Enable CONFIG_MEM_SLAB_POINTER_VALIDATE in the Zephyr configuration to cause a controlled kernel panic on misuse, which prevents silent memory corruption and provides an observable failure mode.

Generated by OpenCVE AI on September 15, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 13 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents. The code then dereferences the NULL gw (gw->gw_id) and passes it to mqtt_sn_gw_destroy(), reaching k_mem_slab_free(&gateways, NULL). With CONFIG_MEM_SLAB_POINTER_VALIDATE enabled this triggers k_panic(); in the default configuration it performs a write through the NULL pointer ((char )mem = slab->free_list;) and corrupts the slab free list. The outcome is a crash/kernel panic or, on targets where address 0 is writable, silent memory-allocator corruption. The vulnerable branch runs whenever the connected MQTT-SN gateway fails to answer keepalive PINGREQs for the configured number of retries. This condition is controlled by the remote peer: a malicious or compromised gateway, or an on-path/adjacent attacker that advertises itself as a gateway and then stops responding (or blackholes the real gateway's PINGRESPs), forces the client into the defect. MQTT-SN runs over UDP and no authentication is required. The impact is a remotely triggerable denial of service (availability) of the affected MQTT-SN client; there is no attacker-controlled data written. The sibling remover process_advertise() uses SYS_SLIST_FOR_EACH_CONTAINER_SAFE and is not affected. The fix assigns the macro's return value to gw.
Title NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T13:00:29.219Z

Reserved: 2026-07-15T17:38:07.683Z

Link: CVE-2026-15891

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:06.532Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T23:16:27.870

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-15891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses